Most lawyers think of cybersecurity as an IT decision, something the firm will get to when the budget allows. The bar disagrees. The rules of professional conduct treat protecting client information as an ethical obligation attached to the license itself, and the disciplinary framework around technology has been in place for over a decade. A firm that hasn't addressed security hasn't deferred an IT project. It's carrying an unmet professional duty.
The Rules Are Already on the Books
ABA Model Rule 1.6(c), adopted in 2012, requires a lawyer to "make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client." Comment 8 to Rule 1.1, adopted the same year, makes technology part of basic competence: a lawyer must keep abreast of "the benefits and risks associated with relevant technology." Forty states, including Colorado, have adopted the technology competence requirement.
Formal Opinion 477R (2017) lists the measures a lawyer should consider when handling client information electronically: secure internet access, strong and periodically changed passwords, multi-factor authentication, encryption of stored data, security patches applied, and training for everyone assisting in the delivery of legal services. Formal Opinion 483 (2018) goes further: lawyers have a duty to monitor for breaches, to act reasonably and promptly to stop one and mitigate the damage, to determine what happened, and to notify current clients when material confidential information is compromised. "We didn't know we were breached" is itself a compliance failure, because the duty includes watching.
The Numbers Behind the Duty
The ABA's own Legal Technology Survey found that 39% of firms experienced a security breach, and law-firm surveys found that 56% of breached firms lost sensitive client data. Only 34% of firms report having an incident response plan, down from 42% the year before, and only 40% carry cyber liability insurance. Industry analysis puts the average cost of a law firm data breach at $5.08 million.
Law firms are targeted because of what they hold: privileged communications, deal terms, medical records, financial discovery, and trust account access, concentrated in organizations that spend less on security than their clients do. The FBI's Internet Crime Complaint Center recorded $2.8 billion in business email compromise losses in 2024, and phishing was its most-reported crime category, with 193,407 complaints. Those are the attack types that reach a law firm through an inbox, which every firm has and few firms defend.
What "Reasonable Efforts" Means in Practice
The rules don't prescribe specific products, and Opinion 477R rejects a one-size answer. What they require is a risk-based judgment: the sensitivity of the information, the likelihood of disclosure without safeguards, and the cost and difficulty of protecting it. For a firm holding privileged client files, that judgment consistently points to a recognizable baseline.
Multi-factor authentication on email and every system holding client data, because stolen passwords start most compromises. Encryption of client files, in storage and in transit. Patches and updates applied on a schedule rather than when someone remembers. Access limited so each person reaches only the matters they work on. Monitoring capable of detecting an intrusion, since Opinion 483 makes detection itself a duty. Tested backups that can restore the firm's files after ransomware. Training for lawyers and staff, which 477R names explicitly. And a written incident response plan, so the firm's breach obligations, stopping it, assessing it, notifying affected clients, get met under pressure instead of improvised.
The other half is documentation. A disciplinary inquiry or a client's security questionnaire asks the same question: show us what you had in place. A firm that can produce its safeguards, its training records, and its response plan has evidence of reasonable efforts. A firm that can't has an adjective.
Where a Managed IT Partner Helps
Most small and mid-sized firms have no one whose job is any of this. A managed service provider can operate the technical safeguards as an ongoing, proactive service: enforce the multi-factor authentication and encryption, apply the patches, run the monitoring that satisfies the duty to detect, keep the backups tested, and maintain the documentation that demonstrates the firm's efforts. The provider can also support the response plan, so that if a breach occurs, the firm can answer Opinion 483's questions, what happened, what was reached, is it contained, with evidence rather than guesswork.
The ethical duty can't be delegated away, but the reasonable efforts standard is met through competent help, the same way a firm meets its trust accounting obligations with a bookkeeper and its tax obligations with an accountant. What the bar expects is that the firm took the duty seriously, and a documented security program operated by professionals is what taking it seriously looks like.
If you're not confident your firm could show a disciplinary authority, a client, or an insurance carrier the reasonable efforts the rules require, a Network Discovery might be in order. We'll assess how your client data is protected, where your systems are exposed, and what your current safeguards would and wouldn't demonstrate.
Ready to take the next step? Contact the Connecting Point team today to discuss your organization's needs.
Fill out our Network Discovery Form to get started!
970.356.7224 | www.CPcolorado.com | sales@CPcolorado.com
Connecting Point is a trusted IT solutions provider based in Greeley, Colorado, helping businesses across Northern Colorado and beyond navigate technology decisions with confidence.


